Google Associate Cloud EngineerEnsuring successful operation of a cloud solutionEasy
A security team needs to restrict inbound SSH access to all Compute Engine instances in a specific VPC network to only their internal administrative subnet (10.0.1.0/24). All other inbound SSH traffic must be denied. Which network resource should be configured?
- ANetwork Access Control List (NACL)
- BVPC Service Controls
- CVPC firewall rule
- DCloud Armor security policy
Show answer & explanationAnswer & explanation
Correct answer: C. VPC firewall rule
VPC firewall rules are used to control ingress and egress traffic to and from Compute Engine instances based on IP ranges, protocols, and ports. This is the correct tool to restrict SSH access to a specific subnet.
Why the other options are wrong
- A. NACLs are a concept in some cloud providers (like AWS), but Google Cloud uses VPC firewall rules for this functionality.
- B. VPC Service Controls help mitigate data exfiltration risks for Google Cloud services, not direct network access to VMs.
- D. Cloud Armor is a DDoS protection and WAF service, primarily for HTTP(S) load-balanced applications, not for direct SSH access to VMs.
VPC Firewall Rule
A resource in Google Cloud that allows or denies traffic to and from Compute Engine instances in a VPC network based on specified criteria.
- Can be ingress (inbound) or egress (outbound).
- Rules are stateful, meaning return traffic is automatically allowed.
- Can target instances by tags, service accounts, or all instances in the network.
Memory trick: Firewall Rules Guard VM Gates.